CVE-2021-38950: High severity IBM MQ for HPE NonStop vulnerability
Published Dec 13, 2021
·Updated
IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when SharedBindingsUserId is set to effective. IBM X-ForceID: 211404.
Other sources
IBM MQ on HPE NonStop is vulnerable to a privilege escalation attack when SharedBindingsUserId is set to effective.
— IBM
Affected Software
4 affected components
IBM MQ for HPE NonStop<=8.1.0
IBM MQ for HPE NonStop<=8.0.4
IBM MQ for HPE NonStop=8.0.4
IBM MQ for HPE NonStop=8.1.0
Remediation
Patch Available
Event History
Dec 13, 2021
CVE Published
via IBM·12:00 AM
Dec 14, 2021
CVE Published
via MITRE·04:20 PM
Data Sourced
via MITRE·04:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this IBM MQ on HPE NonStop vulnerability?
The vulnerability ID is CVE-2021-38950.
2
Which versions of IBM MQ for HPE NonStop are affected by this vulnerability?
IBM MQ for HPE NonStop versions 8.0.4 and 8.1.0 are affected.
3
What is the severity of CVE-2021-38950?
The severity of CVE-2021-38950 is high, with a CVSS score of 7.8.
4
What is the risk of this vulnerability?
This vulnerability allows for privilege escalation attacks when SharedBindingsUserId is set to effective.
5
How can I fix this vulnerability in IBM MQ on HPE NonStop?
IBM has provided a fix for this vulnerability. Refer to the IBM support page (https://www.ibm.com/support/pages/node/6525810) for more information.